# Corporate Security Engineer
**Company:** [Airwallex](https://scaleengineer.com/companies/airwallex)
As a Corporate Security Engineer at Airwallex, you'll defend enterprise systems and employees from sophisticated threats including malware, phishing, and unauthorized access across a modern corporate environment. This highly technical role combines digital forensics, incident response, and security tool development to protect corporate IT infrastructure, endpoints, and identity providers at a rapidly scaling global fintech organization. You'll need 3+ years of security engineering experience, expertise with tools like CrowdStrike and Splunk, and a strong understanding of attacker techniques and detection methodologies.
**Role:** Security Engineer
**Seniority:** Mid
**Locations:** US - San Francisco
**Salary:** 130000–200000 USD
[Apply](https://jobs.ashbyhq.com/airwallex/be298e1a-9eed-4845-bc5c-57bf1aaa5589)
Canonical: https://scaleengineer.com/jobs/airwallex/corporate-security-engineer
---
## Responsibilities

- Incident Response and Digital Forensics: Lead and contribute to incident response efforts for malware infections, phishing campaigns, and unauthorized access incidents. Conduct thorough digital forensics investigations to determine attack vectors, scope of compromise, and remediation strategies.
- Security Control Design and Development: Design, develop, test, and evaluate new corporate security controls tailored for a rapidly growing business environment. Implement technical solutions that balance security rigor with operational efficiency to enable fast business growth.
- Threat Hunting and Log Analysis: Proactively hunt through security log sources using SIEM and endpoint detection platforms to identify anomalous behavior, emerging threats, and indicators of compromise across the corporate environment.
- Security Alert and Workflow Implementation: Design and implement automated security alerts, detection rules, and incident response workflows that support the complete incident response lifecycle from detection through remediation and closure.
- Corporate Infrastructure Security: Secure and maintain corporate IT infrastructure including identity providers, endpoints, corporate networks, and cloud platforms. Identify vulnerabilities, implement remediation measures, and maintain compliance with security standards.
- Security Tool Deployment and Operations: Deploy, configure, and operationalize security tooling across the enterprise with a strategic focus on maximizing security impact. Manage endpoint protection, mobile device management, and identity and access management solutions.

## Requirements

### education

- {"name":"Bachelor's Degree in Computer Science or Cybersecurity","description":"Bachelor's degree in Computer Science, Cybersecurity, Information Security, or a closely related technical discipline required."}

### technical

- {"name":"Security Monitoring and SIEM Tools","description":"Expert-level proficiency with CrowdStrike, Splunk, or equivalent security monitoring and incident response platforms for log analysis, threat detection, and investigation."}
- {"name":"Endpoint Detection and Response (EDR)","description":"Deep hands-on experience with EDR solutions including CrowdStrike Falcon, with ability to configure detection rules, investigate alerts, and remediate endpoints."}
- {"name":"Identity and Access Management","description":"Working knowledge of cloud-based identity platforms like Okta and Google Workspace, including authentication mechanisms, access control policies, and security configurations."}
- {"name":"Endpoint Management","description":"Experience with mobile device management (MDM) and endpoint management tooling such as Kandji, Intune, or similar platforms for corporate device security."}
- {"name":"Cloud Security","description":"Practical experience securing infrastructure across cloud platforms including GCP, Alibaba Cloud, or equivalent, with understanding of cloud-native security controls."}
- {"name":"Network Security and VPN","description":"Understanding of corporate network architecture and experience with cloud-based VPN services for secure remote access and threat detection."}
- {"name":"Scripting and Automation","description":"Proficiency with scripting languages such as Python, Bash, or PowerShell to automate security workflows, develop detection logic, and improve incident response efficiency."}
- {"name":"Digital Forensics","description":"Hands-on experience conducting digital forensics investigations on endpoints and systems, including evidence collection, analysis, and chain of custody."}
- {"name":"Threat Analysis and Attacker Techniques","description":"In-depth understanding of common attacker tools and techniques (MITRE ATT&CK framework), ability to recognize malware behavior, and knowledge of detection and prevention strategies."}

### experience

- {"name":"Security Engineering or Incident Response","description":"Minimum 3+ years of professional experience working as a security engineer, incident responder, or security operations analyst in a technology company environment."}
- {"name":"Corporate Security Environment","description":"Experience defending corporate IT environments against real-world threats including malware, phishing, and unauthorized access attempts."}
- {"name":"Investigation and Problem-Solving","description":"Demonstrated ability to conduct in-depth investigations with high quality analysis, strong judgment in threat assessment, and evidence-based decision making in security incidents."}
- {"name":"High-Growth Startup Context","description":"Experience working in fast-paced, high-growth technology companies where balancing security with business velocity and rapid scaling is essential."}

## Skills

### required

- {"name":"CrowdStrike Falcon","description":"Expert-level experience with CrowdStrike endpoint detection and response platform for threat detection, investigation, and endpoint remediation."}
- {"name":"Splunk","description":"Proficient with Splunk Security Information and Event Management for log ingestion, analysis, threat hunting, and creating detection rules."}
- {"name":"Incident Response","description":"Ability to rapidly investigate security incidents, document findings, communicate with stakeholders, and execute remediation with high quality and thoroughness."}
- {"name":"Malware Analysis and Detection","description":"Understanding of malware behavior, ability to detect and analyze malicious code, knowledge of detection methodologies and prevention techniques."}
- {"name":"Phishing Investigation","description":"Experience investigating phishing campaigns, understanding attack vectors, and implementing controls to prevent and detect phishing at scale."}
- {"name":"Cloud Platform Security","description":"Familiarity with securing infrastructure across cloud platforms with understanding of cloud-native security controls and threats."}
- {"name":"Technical Communication","description":"Ability to explain complex security, infrastructure, and software concepts to non-technical stakeholders, executives, and business teams."}
- {"name":"Linux and Windows Administration","description":"Working knowledge of Linux and Windows system administration, log files, system hardening, and security configuration."}

### preferred

- {"name":"Python Scripting","description":"Experience with Python for automation scripts, security tool integration, and developing custom detection logic for security tools."}
- {"name":"Bash and PowerShell","description":"Proficiency with Bash and PowerShell scripting for automating security workflows, system administration, and investigation tasks."}
- {"name":"Okta Administration","description":"Hands-on experience configuring and securing Okta identity platforms, including authentication policies and access controls."}
- {"name":"Mobile Device Management (MDM)","description":"Experience deploying and managing enterprise MDM solutions like Kandji or Microsoft Intune for securing corporate devices."}
- {"name":"Google Cloud Platform (GCP)","description":"Practical experience with GCP security features, cloud security architecture, and securing cloud-native workloads."}
- {"name":"MITRE ATT&CK Framework","description":"Deep familiarity with MITRE ATT&CK framework for mapping attacker techniques, building detection strategies, and threat analysis."}
- {"name":"Threat Intelligence","description":"Experience consuming and applying threat intelligence to identify threats specific to fintech, payments, and financial services sectors."}
- {"name":"Security Compliance and Standards","description":"Knowledge of security compliance frameworks such as ISO 27001, SOC 2, or PCI DSS relevant to fintech companies."}

## Tech stack

### tools

- {"name":"CrowdStrike Falcon","description":"Enterprise endpoint detection and response (EDR) platform for detecting threats, investigating compromises, and managing endpoints across the corporate environment."}
- {"name":"Splunk","description":"Security Information and Event Management (SIEM) platform for centralized log collection, analysis, threat hunting, and security investigations."}
- {"name":"Okta","description":"Cloud-based identity and access management platform for securing user authentication, managing access controls, and protecting against identity-based threats."}
- {"name":"Google Workspace Security","description":"Google's cloud productivity suite with integrated security controls including email security, device management, and data protection."}
- {"name":"Kandji","description":"Apple-focused mobile device management platform for securing corporate macOS and iOS devices with compliance and security controls."}
- {"name":"Microsoft Intune","description":"Microsoft's mobile device management and application management solution for securing Windows, iOS, and Android devices."}
- {"name":"Google Cloud Platform (GCP)","description":"Cloud computing platform used for infrastructure deployment, security monitoring, and protecting cloud-native workloads."}

### others

- {"name":"Digital Forensics Tools","description":"Expertise with forensic investigation tools for evidence collection, analysis, and incident response on endpoints and systems."}
- {"name":"MITRE ATT&CK Framework","description":"Comprehensive framework for understanding attacker tactics, techniques, and procedures used in threat modeling and detection strategy development."}
- {"name":"Incident Response Workflows","description":"Design and implementation of structured incident response processes including detection, investigation, containment, eradication, and recovery."}
- {"name":"Threat Intelligence","description":"Integration and application of threat intelligence data to identify threats, understand attacker motivations, and improve detection capabilities."}

### databases

### languages

- {"name":"Python","description":"Used for security automation, threat hunting scripts, and developing custom detection logic for security platforms."}
- {"name":"Bash","description":"Used for Linux system administration, incident response scripting, and security tool automation."}
- {"name":"PowerShell","description":"Used for Windows system administration, incident response workflows, and security tool integration on Windows endpoints."}

### frameworks

## Benefits

### benefits

- {"name":"Equity and Stock Options","description":"Participate in Airwallex's equity program as part of your compensation package, with ownership stake in a $11 billion valued fintech platform."}
- {"name":"Comprehensive Health Insurance","description":"Access to medical, dental, and vision coverage with employer contributions to support your health and wellness."}
- {"name":"Professional Development and Learning","description":"Budget and support for security certifications, training courses, conference attendance, and continuous learning in cybersecurity and incident response."}
- {"name":"Flexible Work Arrangements","description":"Work arrangement flexibility supporting both collaboration and focused deep work for security investigations and engineering tasks."}
- {"name":"Retirement Planning","description":"Competitive retirement benefits including employer matching contributions to help you plan for long-term financial security."}
- {"name":"Paid Time Off","description":"Generous paid vacation, sick leave, and personal days to maintain work-life balance while working on high-impact security initiatives."}
- {"name":"Global Team and Mobility","description":"Opportunity to work with security professionals across 27 offices globally, with potential for travel and international collaboration."}

## Compensation

- **max:** 220000
- **min:** 160000
- **currency:** USD
- **stockOptions:** true

## Interview process

### steps

- {"name":"Initial Screening and Resume Review","description":"Hiring team reviews your resume, experience, and background for alignment with core security engineering and incident response requirements. This step typically takes 3-5 business days."}
- {"name":"Technical Phone Screening","description":"Conversation with a security engineer or technical recruiter covering your background in incident response, familiarity with security tools like CrowdStrike and Splunk, understanding of attacker techniques, and specific experience with corporate security environments."}
- {"name":"Technical Deep-Dive Interview","description":"Detailed technical discussion with security engineers on your experience with digital forensics, incident response case studies, knowledge of detection mechanisms, tool deployment experience, and approach to threat hunting and investigation."}
- {"name":"System Design and Problem-Solving Interview","description":"Evaluation of your ability to design security controls, create detection workflows, architect security solutions for a scaling business, and approach complex security challenges with technical depth and business pragmatism."}
- {"name":"Team and Culture Fit Discussion","description":"Conversation with Information Security leadership or team members about your collaboration style, communication skills, ability to work in fast-paced environments, and alignment with Airwallex's operating principles and values around speed, rigor, and ownership."}
- {"name":"Final Review and Offer","description":"Hiring team reviews interview feedback, technical assessment results, and overall candidate profile. Successful candidates receive offer discussion covering compensation, equity, benefits, and role expectations."}

## Full description
## **About Airwallex**

Airwallex is the only unified payments and financial platform for global businesses. Powered by our unique combination of proprietary infrastructure and software, we empower over 250,000 businesses worldwide – including Brex, Rippling, Navan, Qantas, SHEIN and many more – with fully integrated solutions to manage everything from business accounts, payments, spend management and treasury, to embedded finance at a global scale.

Proudly founded in Melbourne, we have a team of over 2,300 of the brightest and most innovative people in tech across 27 offices around the globe. Valued at US$11 billion and backed by world-leading investors including T. Rowe Price, Visa, Mastercard, Robinhood Ventures, Sequoia, Salesforce Ventures, DST Global, and Lone Pine Capital, Airwallex is leading the charge in building the global payments and financial platform of the future. If you’re ready to do the most ambitious work of your career, join us.

## **Attributes We Value**

We hire successful builders with founder-like energy who want real impact, accelerated learning, and true ownership. You bring strong role-related expertise and sharp thinking, and you’re motivated by our mission and [operating principles](https://www.airwallex.com/us/operating-principles). You move fast with good judgment, dig deep with curiosity, and make decisions from first principles, balancing speed and rigor.

You're humble and collaborative; turn zero‑to‑one ideas into real products, and you “get stuff done” end-to-end. You use AI to work smarter and solve problems faster. Here, you’ll tackle complex, high‑visibility problems with exceptional teammates and grow your career as we build the future of global banking. If that sounds like you, let’s build what’s next.

## **About the team**

Airwallex’s Information Security team partners closely with engineering, IT, and other stakeholders to protect our systems, data, and employees while enabling the business to move quickly. The team helps build and maintain strong security practices across the company—from secure product and infrastructure design to risk reduction, incident response, audits, and compliance—so security is built into how we operate, not treated as a blocker.

**What You'll do**

As a Corporate Security Engineer, you will be a critical part of defending Airwallex’s enterprise systems and employees from threats such as malware, phishing and unauthorised access.

This role is a highly technical opportunity to detect, investigate and prevent security issues across a modern corporate environment. You will work on digital forensics, incident response and tool development and deployment, protecting a range of corporate IT platforms from endpoints to identity providers.

This role is based in San Francisco

**Responsibilities:**

* Contribute to incident response for malware, phishing, digital forensics.
* Design, develop, test, and evaluate new corporate security controls for a rapidly growing business.
* Perform incident response and hunt through log sources to identify new threats.
* Design and implement security alerts and workflows to support the incident response lifecycle.
* Secure corporate IT infrastructure and remediate issues across identity providers, endpoints, corporate networks and other platforms.
* Deploy, configure and operate security tooling with a laser focus on impact.

**Who you are**

We’re looking for people who meet the minimum qualifications for this role. The preferred qualifications are great to have, but are not mandatory.

**Minimum Qualifications:**

* A passion for solving the complex challenges of high-growth startups.
* Self motivation and drive to learn new skills, or dive deeper into existing skills.
* Bachelor's degree in Computer Science, Cybersecurity or similar.
* 3+ years working in a security engineering or incident response role within a tech company.
* Strong experience with Crowdstrike, Splunk or other common security monitoring tools.
* In depth understanding of common attacker tools and techniques, how they can be detected and prevented, and ability to respond to incidents with high depth and quality of investigation.
* Experience with GCP, Alibaba Cloud or other cloud platforms is preferred.
* Experience with Okta, Google Workspace and cloud-based VPN services is preferred.
* Experience securing endpoints, including with MDM tooling such as Kandji, Intune
* Strong communication skills with the ability to explain technical security and software concepts to a non-technical audience.

**Preferred Qualifications:**

* Strong Engineering mindset with scripting experience such as with Python, Bash, Powershell.

## **Applicant Safety Policy: Fraud and Third-Party Recruiters**

_To protect you from recruitment scams, please be aware that Airwallex will not ask for bank details, sensitive ID numbers (i.e. passport), or any form of payment during the application or interview process. All official communication will come from an @_[_airwallex.com_](http://airwallex.com) _email address. Please apply only through_ [_careers.airwallex.com_](http://careers.airwallex.com) _or our official LinkedIn page._

_Airwallex does not accept unsolicited resumes from search firms/recruiters. Airwallex will not pay any fees to search firms/recruiters if a candidate is submitted by a search firm/recruiter unless an agreement has been entered into with respect to specific open position(s). Search firms/recruiters submitting resumes to Airwallex on an unsolicited basis shall be deemed to accept this condition, regardless of any other provision to the contrary._

## **Equal opportunity**

Airwallex is proud to be an equal opportunity employer. We value diversity and anyone seeking employment at Airwallex is considered based on merit, qualifications, competence and talent. We don’t regard color, religion, race, national origin, sexual orientation, ancestry, citizenship, sex, marital or family status, disability, gender, or any other legally protected status when making our hiring decisions. If you have a disability or special need that requires accommodation, please let us know.
